Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:31:18 UTC APT group: IAmTheKing Names IAmTheKing (Kaspersky) Country Russia Motivation Information theft and espionage First seen 2018 Description (Kaspersky) On October 1, 2020, the DHS CISA agency released information about a malware family called SlothfulMedia, which they attribute to a sophisticated threat actor. We have been tracking this set of activity through our private reporting service, and we would like to provide the community with additional context. In June 2018, we published the first report on a new cluster of activities that we named IAmTheKing, based on malware strings discovered in a malware sample from an unknown family. Amusingly, other strings present inside of it invited “kapasiky antivirus” to “leave [them] alone”. Observed Sectors: Defense, Education, Energy, Government. Countries: Malaysia, Russia, Ukraine. Tools used JackOfHearts, KingOfHearts, LaZagne, Mimikatz, ProcDump, PsExec, QueenOfClubs, QueenOfHearts. Information Last change to this card: 19 October 2020 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=e29e1820-caf6-420b-b4ba-f33391e48cfb https://apt.etda.or.th/cgi-bin/showcard.cgi?u=e29e1820-caf6-420b-b4ba-f33391e48cfb Page 1 of 1